On 13/12/17 11:58, Tim Shirley wrote:
> So many of the arguments made here, such as this one, as well as the recent 
> demonstrations that helped start this thread, focus on edge cases.  And while 
> those are certainly valuable to consider, they obscure the fact that “Green 
> Bar” adds value in the mainstream use cases.  If we were talking about how to 
> improve EV, then by all means focus on the edge cases.  The thing I don’t see 
> in all this is a compelling argument to take away something that’s useful 
> most of the time.

My concern with this argument is that it's susceptible to the criticism
that Adam Langley made of revocation checking:
https://www.imperialviolet.org/2012/02/05/crlsets.html

"So [EV identity is] like a seat-belt that snaps when you crash. Even
though it works 99% of the time, it's worthless because it only works
when you don't need it."

Gerv
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to